What Makes an Effective Chief Risk Officer
Norman Marks, CRMA, CPA, was a chief audit executive and chief risk officer at major global corporations for more than 20 years. The views expressed in this blog are his personal views and may not represent those of The IIA.
One of the comments I received is that the same or similar list could be used to define the necessary attributes of an effective chief risk officer (CRO).
I think that is right, with special emphasis added in three areas:
- The CRO has to have an excellent understanding of the business, the organization structure and key players, how it delivers value to its stakeholders, and where the opportunities as well as the potential hazards lie. It is simply not enough to be a technical expert. The CRO has to get out and be among those in the front lines if he is to understand how the enterprise really works.
- The CRO must be able to communicate and influence at all levels of the business. He must be fluent in the language of ths business and not try to express himself using the techno-babble of risk management. The CRO must not only be able to gain the attention of key decision-makers, but be able to engage them so that they listen, pay attention, and accept him as a valuable advisor.
- The CRO must step out of the shadows of the consultants who propose quarterly risk reviews of the top ten or twenty risks, and seek to help the organizations understand and manage all the more significant risks to the success of the organization — including helping the people in the front lines make better decisions every day because they have and are considering risk information. The CRO must help the organization manage the risks that matter at the speed of tyhe business.
To illustrate my second point, let me share a story. A couple of years ago, I made a presentation at a meeting of a professional risk management organization. Afterwards, we adjourned to lunch where I was asked by their president to sit with him. He had a problem and asked for my advice.
This individual was the CRO at a major organization. While he was able to get periodical meetings with the CEO, he felt that he had little influence and was not invited to key strategy and other meetings. He said that the CEO didn't really listen and always cut their meetings short.
As I listened, I realized I didn't want to spend time with him either! He was boring. He used the technical language and presented himself as a technical risk manager, not as somebody who understood and sought to improve business performance. He was a brake on the organization without constructive ideas.
This type of CRO will not be a credible partner to the CEO and top executives. He needs to learn executive presence and presentation skills. But, more to the point, he needs to rethink himself as a business executive rather than a technocrat.
But going back to the list of attributes in the guidance referenced in the earlier post. I wonder how many CROs have the majority of those skills?
I welcome your views.
Posted on Jun 25, 2013 by Norman Marks
Share This Article: